AES Encrypt & Decrypt
Encrypt or decrypt text with a password.
- Free
- No signup
- Nothing uploaded
- No watermark
Direction
Message
Password
AES-256-GCM with PBKDF2 key stretching, run by your browser's own crypto engine. Nothing is uploaded — but a browser tool is for learning and light use, not for protecting something whose loss would matter.
How to Encrypt Text with AES and a Password
Sometimes a note has to travel through a channel you do not fully trust: a shared chat, an email thread, a text file in a cloud folder. This page scrambles that text with AES-256 so it reads as a long run of random letters, and only someone who knows the password can turn it back.
You type the message, choose a password and press Encrypt. To read it again, switch the Direction to Decrypt, paste the scrambled string, enter the same password and press Decrypt. Your browser’s built-in crypto engine does the work, so neither the message nor the password travels to us.
No software to install Free Works on any device
Steps to Encrypt and Decrypt a Message
-
1. Leave the direction on Encrypt
Encrypt is selected when the page opens. Type or paste the words you want to hide into the Message box. Any plain text works, including Hindi, Tamil and emoji.
-
2. Choose a strong password
Type it into the Password box. Pick something long that the other person can remember, or that you can pass on by a different route such as a phone call. There is no reset if it is lost.
-
3. Press Encrypt and copy
A Result panel appears with the encrypted text. Copy it and send or store it wherever you like. It is only letters, digits and a few symbols, so it survives email and chat apps.
-
4. Switch to Decrypt to read it
Choose Decrypt, paste the encrypted string into the Encrypted text box, type the password and press Decrypt. The original message comes back in the Result panel.
What Is AES Encryption?
AES, the Advanced Encryption Standard, is the cipher that banks, governments and messaging apps rely on to protect data. This tool uses its 256-bit form in GCM mode, which also detects tampering: if even one character of the encrypted text changes, decryption refuses instead of handing you garbled words.
A password is not used as the key directly. It is stretched with PBKDF2 over 310,000 rounds of SHA-256 together with a random salt, which makes guessing slow and costly for an attacker. The salt and a random starting value are packed into the output, so encrypting the same message twice gives two different strings.
Why Use Security and Crypto Tools Locally?
Hashes, keys, tokens and passwords are exactly the things you should not paste into a stranger’s server. Here they are made and checked inside your browser, so secrets stay on the machine in front of you.
“A secret generated on your own device stays yours.”
- Strong random passwords
- Keys generated on your device
- Two-factor codes for testing
- Files checked against checksums
- Hashes in every common algorithm
- JWTs decoded and checked
- Security headers written for you
- No secrets sent anywhere
Popular Uses for Hash and Key Generators
Developers and careful users reach for these during everyday security work.
- New passwords Generate a long random password or passphrase for a new account.
- Verifying downloads Hash a file with SHA-256 and compare it with the value the publisher lists.
- Debugging logins Decode a JWT to see its claims and check the signature with your secret.
- SSH and API keys Create an RSA or Ed25519 key pair or an API key for a new service.
- Website headers Write a Content Security Policy and other security headers for a web server.
- Testing two-factor login Generate TOTP codes and secrets to test an authenticator setup during development.
- Script integrity Make an SRI hash so a browser can tell if a CDN script was changed.
- Password strength Measure how many guesses a password would take, using its entropy.
What the AES Tool Does
AES-256-GCM
The same strong mode that protects HTTPS traffic, with a built-in check that the text was not altered after encryption.
Password stretching
PBKDF2 with 310,000 iterations and a fresh random salt every time, in line with current OWASP guidance for SHA-256.
Both directions on one page
One switch moves between Encrypt and Decrypt, and the box labels change so you always know which job you are doing.
Your browser does the maths
The Web Crypto engine inside Chrome, Edge, Firefox and Safari performs every step. Nothing is logged or sent.
Paste-safe output
The result is Base64 text, which can go into WhatsApp, email or a notes app without breaking along the way.
Why Use ToolXkit for AES Encrypt & Decrypt?
Your files stay with you
Everything runs inside your browser. Nothing you open or type is uploaded to a server.
Free, with no catch
No signup, no watermark and no daily limit on how often you use it.
Fast
Results appear in seconds, because nothing has to travel over the internet and back.
Works on any device
Use it on a computer, tablet or phone, in Chrome, Edge, Firefox or Safari.
Nothing to install
No app, no extension and no desktop program. Open the page and start.
Made for real people
Plain words and clear buttons, built by one developer who wanted tools like this to exist.
Crypto Tools for Different Users
Web developers
Create security headers, SRI hashes and JWTs while building and testing apps.
System administrators
Generate SSH keys, check fingerprints and verify file checksums on the go.
Security testers
Decode tokens, inspect PEM files and test HMAC signatures without extra tooling.
Computer science students
See how hashing, encryption and key pairs behave by trying them yourself.
Everyday users
Make strong passwords and passphrases that are never sent over the internet.
IT teams
Create API keys and OAuth values for new integrations in a safe place.
Best Times to Generate a Key or Hash
Local crypto tools make sense when you are:
- Setting up a new server
- Creating a strong password
- Checking a downloaded installer
- Debugging a sign-in problem
- Adding security headers to a site
- Testing an authenticator app
- Learning how encryption works
- Rotating an old API key
Tips for Password Encryption
-
Share the password through a different route from the encrypted text. Putting both in one email defeats the purpose.
-
A passphrase of four or five unrelated words is stronger, and easier to remember, than a short jumble of symbols.
-
If Decrypt fails, check the password first, then check that the whole string was copied. A missing last character is enough to stop it.
-
Only text encrypted on this page can be decrypted here, because the salt and starting value are stored in a layout specific to this tool.
-
Treat it as a handy tool for notes and light use. For company secrets or legal records, use a dedicated password manager or encrypted archive.
Frequently Asked Questions
Answers to common questions about this tool.
Is AES-256 encryption safe to use?
Yes. AES-256 has no known practical break, and it is approved for classified information by several governments. In practice the weak point is the password. A short or common password can be guessed, so choose a long one and keep it private.
Why does the same message give a different result each time?
Each run picks a new random salt and a new starting value. That is deliberate: it stops anyone from spotting that two encrypted notes contain the same words. Both outputs decrypt to the same text with the same password.
Can a lost password be recovered?
The text cannot be recovered. There is no back door, no reset link and no copy kept on any server. That is exactly what makes the encryption trustworthy, so store the password somewhere safe.
Why does it say it cannot tell whether the password is wrong or the text was changed?
GCM mode checks a tag at the end of the data. A wrong password and a modified string both make that check fail in the same way, so the tool honestly reports that either could be the cause.
Can I encrypt a file with this?
No, this page works on text you type or paste. For a document, protect the file itself, for example with a password-protected ZIP or PDF, or paste the text content here if it is short.
Can someone decrypt this with another AES tool?
Only if that tool uses the same layout: a 16-byte salt, a 12-byte starting value, PBKDF2 with 310,000 SHA-256 rounds, then the GCM data, all in Base64. Most online tools use different settings, so decrypt on this page.
Are the keys and passwords made here truly random?
They come from the browser’s built-in secure random number generator, the same source used for encrypted connections. That is suitable for passwords, keys and tokens.
Does AES Encrypt & Decrypt send my secrets to a server?
No. Everything is worked out locally, and what you type or generate is neither uploaded nor logged. For real production keys, it is still wise to generate them on the machine where they will be used.
Is AES Encrypt & Decrypt free for commercial projects?
Yes. Use it for personal, work or client projects at no cost and without an account. What you generate belongs to you, and the site keeps no copy.
Can a hash be reversed to get the original text?
No. A hash is one-way. Short or common passwords can still be guessed by trying many candidates, which is why a long, random password matters more than the hash you pick.
Further reading
- Hash Functions (NIST) NIST’s page on approved hash functions such as SHA-2 and SHA-3.
- RFC 7519: JSON Web Token (IETF) The standard that defines JSON Web Tokens and the claims inside them.
- RFC 6238: TOTP (IETF) The standard behind the six-digit codes shown in authenticator apps.
More Security & Crypto Tools
Other free tools for the same kind of job.
- Adler-32 Calculator Work out the Adler-32 checksum used inside zlib. Open tool
- AES Key Generator Generate a random AES-128 or AES-256 key. Open tool
- API Key Generator Generate API keys with a readable prefix and real entropy behind them. Open tool
- Bulk Password Generator Generate hundreds of strong passwords at once, with no modulo bias. Open tool
- Checksum Calculator CRC-32, CRC-16 and Adler-32 for any text or file, side by side. Open tool
- CORS Header Generator Build CORS headers, with the wildcard-plus-credentials trap caught. Open tool
- CRC16 Calculator Work out CRC-16, both the ARC and CCITT variants. Open tool
- CRC32 Calculator Work out the CRC-32 checksum used by ZIP, PNG and gzip. Open tool
- CSP Generator Build a Content-Security-Policy, with the weak settings called out. Open tool